GoMuseum 隐私政策
1. 我们是谁
GoMuseum("我们")是一款博物馆导览应用,提供拍照识别展品、AI 讲解、语音播放与问答功能。数据控制者联系方式:appcraft008@gmail.com。
GoMuseum is a museum guide app offering artwork recognition, AI-generated narration and Q&A. Data controller contact: appcraft008@gmail.com.
2. 我们收集哪些数据、为什么
| 数据 / Data | 用途 / Purpose | 保留 / Retention |
|---|---|---|
| 账号信息:邮箱、用户名(或 Google 账号基本资料) | 创建与登录账号、找回访问权限 | 至账号删除 |
| 展品照片(拍照识别时) | 仅用于实时识别展品,默认临时处理、不存储原图,处理完成即丢弃 | 不保留 |
| 你主动发送给我们的照片(识别没认准时,应用会问「把这张照片发给我们?」,默认不勾选;只有你勾选发送才会保存),以及你可选填的补充说明、你当时搜索的文字或说明牌上的文字、你最终找到的作品 | 只用于三件事:补录我们还没收录的作品、为缺图的作品寻找有授权的图片并核对是不是同一件、找出识别失败的原因。不对外展示,不加入识别用的参考图库。不勾选不影响任何功能 | 最长 90 天,处理完即提前删除;删除账号时一并删除(见第 4 节)。照片删除后只保留不含图像的记录(识别分数、你找到的作品) |
| 识别事件:图片指纹、识别到的作品与置信度、所在馆、语言 | 两个用途:①改进识别准确率、统计哪些展品被拍到却认不出,据此优先补充资料;②生成你的「足迹」——登录状态下拍照识别时会记下你的账号,让你能在应用内回看拍过哪些作品。你可以在足迹页逐条删除,也可以随时导出 | 与账号的关联至账号删除或你自行删除;去除账号关联后的统计记录长期保留 |
| 设备标识符 | 免费额度管理与防滥用 | 至账号删除 |
| 大致位置(仅在你授权定位时) | 用于在首页显示你身边的博物馆。位置只在你的手机上用来计算与各馆的距离,不会上传到我们的服务器,也不会与任何第三方共享。你可以随时在系统设置中关闭定位权限 | 不保留(不离开你的设备) |
| 诊断数据(崩溃日志、性能) | 改进应用稳定性 | 最长 90 天 |
| 使用统计:应用打开、页面浏览、会话时长,以及设备型号与系统版本 | 了解哪些功能被使用、改进产品。由 Google Firebase 采集(见第 3 节)。我们不采集广告标识符 | 依 Firebase 默认设置 |
| 你提交的反馈:你在反馈框里自己填写的文字,以及反馈指向的坐标(哪个馆、哪件作品、哪个语种、哪类问题)、App 版本与系统、设备标识符;登录状态下还会记下你的账号 | 修正内容与音频里的错误、改进应用。这是我们唯一能得知"某件作品的讲解写错了 / 念错了"的渠道——AI 生成的内容由自动校验把关,但错漏最终靠用户告诉我们。请不要在反馈内容里填写个人信息,我们不需要它 | 文字内容至账号删除(见第 4 节);去除关联后的缺陷坐标长期保留,直至该内容被修正 |
| 交易记录:购买时间、商品、金额、订单号 | 发放与核验通票权益、退款处理、会计与税务留存 | 删除账号后仍保留(见第 4 节) |
We collect account info (email/username) for authentication; photos are processed ephemerally for recognition only and not stored by default. Only if you choose to send us a photo (when recognition misses, the app asks "Send us this photo?" — unchecked by default; declining changes nothing) do we keep it, together with your optional note, what you searched for or the label text, and the artwork you eventually found. We use it only to add missing works, find and verify licensed images for works we lack images for, and diagnose recognition failures — never shown to anyone, never added to the recognition reference library, kept at most 90 days (deleted earlier once handled) and deleted with your account. Recognition events (image fingerprint, matched artwork, confidence) improve accuracy and, when you are signed in, power your in-app "Footprints" history — you can delete entries individually or export them. Device identifiers manage free quota. Approximate location (only if you grant permission) is used to show museums near you on the home screen — it is used only on your device to compute distances, never uploaded to our servers or shared with anyone, and you can turn it off anytime in your system settings. Crash reports and default usage analytics come from Google Firebase — no custom events, no advertising ID. Feedback you submit (your free-text message plus what it points at: museum, artwork, language, issue type, app version, device) lets us fix errors in our AI-generated narration and audio — please do not include personal information in it; we do not need it. Transaction records are retained after account deletion for accounting and tax obligations (see section 4).
3. 数据如何被处理(第三方处理者)
- 识别与讲解由 AI 服务提供商(OpenAI)按我们的指示处理:照片与作品名称会传输给其 API 用于生成结果,不用于其模型训练(依据 OpenAI API 数据政策)。
- Google 登录由 Google 提供。崩溃报告与使用统计由 Google Firebase 提供(Firebase Crashlytics 与 Firebase Analytics):我们只使用其默认的自动统计事件(应用打开、页面浏览、会话),没有自定义埋点,也移除了广告标识符权限,不用于广告或跨应用追踪。
- 应用内购买由 Google Play 结算处理。我们不接触也不存储你的支付方式(银行卡号等)——付款全程在 Google Play 内完成。我们仅从 Google 收到一份购买凭据用于核验并发放通票,并保存订单号、商品、金额与时间。
- 你主动发送的照片存放在 Cloudflare R2 的私有存储中,数据限定保存在欧盟境内(R2 欧盟管辖区);不绑定任何公开网址,只有我们凭专用密钥才能访问。
- 我们不向任何第三方出售你的个人数据,也不用于广告。
Recognition/narration is processed by OpenAI per our instructions (not used for training per OpenAI API policy). Sign-in by Google; crash reporting and default usage analytics by Google Firebase (no custom events, advertising-ID permission removed). Photos you choose to send us are kept in private Cloudflare R2 storage restricted to the EU (R2 EU jurisdiction), with no public address, accessible only to us with a dedicated key. In-app purchases are processed by Google Play Billing — we never see or store your payment method; we receive only a purchase receipt to verify and grant your pass. We never sell your data; no advertising.
4. 你的权利(GDPR/CCPA)
- 删除账号:应用内路径为 设置 → 删除账号,确认后立即生效、不可撤销。
- 删除后会发生什么:
- 永久删除:账号资料(邮箱、用户名)与免费额度记录。
- 足迹与你的关联被切断:识别事件中的账号标识会被清除,这些记录不再指向任何人;去除关联后的统计数据(图片指纹、识别到的作品)作为识别准确率统计保留。
- 你写的反馈文字被删除,缺陷坐标断链保留:你在反馈里填的文字会被真正删除;反馈指向的坐标(哪个馆、哪件作品、哪个语种、哪类问题)会清除账号与设备标识后保留——那一条记的是"这件作品的这个语种有问题",留着才能把内容修好,删了等于把还没修的错误一并抹掉。
- 你主动发送的照片被删除:照片本身、你写的补充说明、你搜索的文字一并删除;只保留不含图像、不指向任何人的记录(识别分数、你找到的作品)。
- 已购通票立即作废且无法找回——重新注册也不行,只能重新购买。通票是消耗型商品,一经发放即在 Google Play 侧完成核销,「恢复购买」不会将其取回。请在删除前确认你的通票已经用完或不再需要。
- 交易记录保留:因会计与税务留存义务,购买记录(订单号、商品、金额、时间)不予删除,但会切断与你身份的关联并清除其中的个人数据(购买凭据原文)。这是法律义务允许的例外,不用于任何其他目的。
- 导出你的数据:发邮件至 appcraft008@gmail.com 申请,我们将在 30 天内以机器可读格式提供,内容包含账号资料、免费额度、足迹、你提交过的反馈、你主动发送的照片(仍在保存期内的照片以限时下载链接提供)与交易记录。
- 你也可通过同一邮箱行使访问、更正、删除、可携带等权利,我们将在 30 天内响应。
Delete your account in-app at Settings → Delete account. This permanently deletes your profile and quota records, and unlinks your footprints — the account identifier is stripped from recognition events, which then point to no one; the de-identified statistics are kept for recognition-accuracy analysis. Photos you chose to send us are deleted, together with your notes and search text. Free text you wrote in feedback is permanently deleted; what that feedback pointed at (museum, artwork, language, issue type) is kept with account and device identifiers stripped, so the reported content error can still be fixed. Any purchased pass is voided immediately and cannot be recovered — passes are consumable products, already consumed on Google Play's side, so "Restore purchases" will not bring them back; re-registering does not restore them either. Transaction records (order ID, item, amount, date) are retained to meet accounting and tax obligations, but are unlinked from your identity and stripped of personal data. To export your data, email appcraft008@gmail.com; we respond within 30 days.
5. 数据安全与存储位置
数据通过 TLS 加密传输;账号与交易等个人数据存储在位于欧盟(法国)的服务器,密码以 bcrypt 加密存储。藏品图片与语音等内容资产存放在 Cloudflare R2 对象存储(不含个人数据);你主动发送的照片存放在另一个 Cloudflare R2 私有存储中,限定在欧盟境内,不可公开访问。我们采取访问控制、速率限制与每日备份等措施保护数据。
Data is encrypted in transit (TLS). Personal data (accounts, transactions) is stored on servers located in the EU (France); passwords are bcrypt-hashed. Media assets (artwork images, audio) are served from Cloudflare R2 and contain no personal data; photos you choose to send us are kept in a separate, private Cloudflare R2 storage restricted to the EU and not publicly accessible.
6. 儿童隐私
本应用不面向 13 岁以下儿童设计,我们不会有意收集儿童个人信息。如你认为我们无意中收集了儿童数据,请联系 appcraft008@gmail.com,我们将予以删除。
This app is not directed to children under 13, and we do not knowingly collect their personal information.
7. 政策更新
政策如有重大变更,我们将在应用内或本页面公告。继续使用即视为接受更新后的政策。